Frequently Asked Questions

Runtime governance, answered plainly

What APERION is, where it sits in your architecture, how it deploys, and how it composes with the tools you already run. Built for the CISO, the Chief Risk Officer, and the teams accountable for what AI agents do in production.

01

Runtime governance & the Trust Fabric

The category, the architecture, and where APERION sits.

What is APERION?

APERION is the runtime governance layer for enterprise AI agents in regulated industries. The product, Smartflow, sits in the call path between an AI agent and the model it uses, enforcing policy on every prompt, response, and tool call, and producing identity-bound audit evidence. It is built for financial services, insurance, healthcare, and defense. See the Trust Fabric.

What is the Enterprise AI Trust Fabric?

It is a four-layer architecture for governing AI agents: verified identity, access governance, runtime governance, and audit and evidence. APERION owns the runtime and audit layers and composes with your existing identity and access stack. Read the Trust Fabric overview.

What is the runtime plane, and why does it matter?

The runtime plane is the call path between any agent and any model: every prompt sent, every response returned, every MCP tool call. It is where data leaves for a model and where policy has to be enforced in real time. Workflow tools decide which agent runs; the runtime plane governs what that agent sends. More in Solutions and on the blog.

What is an AI control plane for enterprise?

An AI control plane is the centralized layer that inventories, monitors, enforces policy on, and audits every AI system across an enterprise, including LLM calls, AI agents, MCP tool connections, and agent-to-agent messages. Smartflow provides this with real-time enforcement rather than after-the-fact observability. See the AI control plane guide.

How is runtime governance different from workflow governance?

Workflow governance decides which agent runs and on whose authority. Runtime governance decides what that agent is allowed to send to a model and what comes back. Different buyers, different failure modes: a workflow failure runs the wrong process; a runtime failure sends regulated data to a public model. APERION composes with workflow tools rather than replacing them.

Who is APERION for?

Regulated enterprises deploying AI agents in production: financial services, insurance, healthcare, and defense. The buyers are usually the CISO, the Chief Risk Officer, and the teams accountable for data exposure and regulatory evidence. See Industries.

Is APERION an observability tool?

No. Observability tells you what happened after it happened. APERION enforces policy inline, in the data path, so a blocked action never reaches the model. It also keeps the evidence record. Enforcement first, evidence second.

02

AI gateway, AI firewall & the runtime plane

The terms buyers search for, and what they mean here.

What is an enterprise AI gateway?

An enterprise AI gateway is an infrastructure layer between your applications and AI model providers that routes, governs, secures, and inspects every AI request. Unlike an API gateway, it handles prompt and response inspection, policy enforcement, semantic caching, and multi-provider routing. Smartflow includes an AI gateway built for on-premises deployment. See the enterprise AI gateway guide.

How is an AI gateway different from an API gateway?

Same pattern, different layer. An API gateway inspects REST headers and payloads. An AI gateway inspects prompts, responses, and tool calls. Different protocols, different controls. You can run both; they do not overlap. See how APERION compares to Kong AI Gateway.

What is an AI firewall, and how is it different from a WAF?

An AI firewall inspects, filters, and enforces policy on every AI request and response in real time. A web application firewall protects against threats like SQL injection and cross-site scripting. An AI firewall addresses AI-specific threats: prompt injection, jailbreaks, sensitive-data exfiltration through prompts, and unsafe model output. Smartflow runs these inline with minimal latency. See the enterprise AI firewall guide.

How do you deploy an AI firewall in front of enterprise LLM applications?

Put a policy enforcement point in the path between your applications and every model they call. Inventory every path to a model, choose an insertion point (gateway, sidecar or SDK), close the bypass so apps cannot reach providers directly, inspect prompts, retrieved content, tool calls and responses, bind every call to a person, monitor before you enforce, and test policies like an attacker. The enterprise AI firewall guide walks through each step.

Is there an AI firewall?

Yes. AI firewalls are an established product category: security layers that inspect prompts, retrieved content, tool calls and responses for enterprise LLM applications. They ship as gateways, reverse proxies, Kubernetes sidecars, SDKs and managed edge services, from security vendors, cloud providers and open-source projects.

Can I build an LLM firewall with open-source tools?

You can assemble one from open-source guardrail libraries, classifiers and a proxy. Budget for keeping detection current as attack techniques change, running it with high availability, and producing audit evidence. Many teams keep simple deterministic checks in the application and put maintained detection at the gateway.

What threats does the runtime plane address?

Prompt injection, jailbreaks, sensitive data leaving for a public model, destructive or out-of-scope tool calls, and agent actions taken without accountability. Independent research through 2026 has shown high attack rates at the agent and application layer. APERION inspects and enforces at the point those actions occur. See Solutions.

Does APERION replace my security stack?

No. APERION adds the layer your current controls do not cover. Data loss prevention, CASB, and API gateways inspect REST traffic. None inspect prompts, responses, or MCP tool calls. APERION sits at the AI boundary and binds every action to a verified identity.

What is semantic caching, and why does it matter?

Semantic caching returns a stored answer when a new prompt is close enough in meaning to a previous one, rather than only on exact text matches. It reduces repeat model calls, which lowers cost and latency. Smartflow includes semantic caching as part of the gateway. See AI cost optimization.

03

Deployment, architecture & performance

Where Smartflow runs and what it takes to run it.

Can Smartflow be deployed on-premises?

Yes. Smartflow runs on-premises, in private cloud, and in hybrid environments, so prompts, responses, and governance data never leave your network. This matters for regulated industries under HIPAA, SEC, the EU AI Act, and data-residency rules. Many competing tools are cloud-only, which routes your AI data through third-party infrastructure. See Smartflow.

Does Smartflow run in air-gapped environments?

Yes. Smartflow is built to run inside the boundary, including air-gapped and sovereign environments where no data plane can leave. This is one reason APERION fits defense and national-security deployments. See Industries.

Do I have to rewrite my applications?

No application rewrite and no model retrain. Smartflow inserts inline at the AI boundary, the way a network control sits in the path of traffic. Applications and agents point at Smartflow, which routes to the model.

What are the system requirements?

Smartflow is containerized and runs on Kubernetes 1.24 or later, on x86_64 or ARM64. Detailed requirements are in the documentation.

What does Smartflow do to latency?

Smartflow is designed to add minimal overhead on the inline path, and semantic caching can reduce latency for repeated or similar prompts by avoiding a model round trip. Benchmark detail is available in the docs and under NDA.

Is Smartflow built for high availability?

Yes. Smartflow runs in production with multi-provider failover, so a single provider outage or rate-limit event does not stop traffic. High-availability deployment patterns are covered in the documentation.

Cloud, private cloud, or on-premises: which should we choose?

Regulated buyers usually run on-premises or in private cloud so the data plane stays inside their boundary. Smartflow supports all three and can route to a permitted cloud provider when policy allows.

04

Identity, agents & MCP

Who acted, on whose behalf, and whether it was allowed.

How does APERION handle AI agent identity?

APERION gives each agent a cryptographic identity and maintains a registry of agents, so every action can be tied to a specific principal and to the human who authorized it. This is the basis for identity-bound audit. See the Trust Fabric.

What is identity-bound audit?

Every AI action is recorded and anchored to a verified identity, so an auditor can trace what an agent did back to the human on whose behalf it acted. The records are tamper-evident. See Solutions.

Does APERION govern MCP tool calls?

Yes. Smartflow inspects and enforces policy on Model Context Protocol tool calls, not just prompts and responses. Tool calls are where agents act on systems, so they are governed in the same path. The open-source APERION Shield focuses on MCP.

What is an AI agent firewall?

An AI agent firewall applies policy to what an agent does as well as what it says: which tools and MCP servers it may call, with which arguments, on whose delegated authority, and what happens when it exceeds that authority. It extends prompt and response inspection to actions.

How can AI agents securely access data across multiple enterprise applications?

Route every agent call through one enforcement point. Give each agent an identity bound to the human it acts for, scope its credentials to that person's permissions, inspect tool arguments and returned content, and log each call with the person, agent, tool and policy decision. See the AIDA agent identity guide.

What about agent-to-agent communication?

Agent-to-agent messages pass through the same runtime plane and are subject to the same inspection, policy, and evidence. As agents call other agents, the chain stays accountable.

What is verified-human step-up?

For higher-risk actions, Smartflow holds the action in the path and sends it back to the human whose authority the agent is using, through the proofing you already run, at NIST IAL2/AAL2. It puts the accountable human back in the loop at the moment of risk.

What is the verified-identity layer?

Your proofing provider verifies who the human is before access is granted, at NIST IAL2/AAL2, and Smartflow enforces it. That defeats synthetic-employee and impersonation fraud at onboarding, and the agent then inherits that verified identity through the rest of the stack.

How does APERION work with my identity provider?

APERION composes with the identity and access stack you already run: Okta, Microsoft Entra, Active Directory, Veza, SGNL, and SAML or Kerberos single sign-on. Smartflow reads identity from your OIDC provider on every request and binds each runtime action to that identity for audit. It works alongside your access layer rather than replacing it.

05

Models, providers & optionality

One control plane across every model you use.

Which model providers does Smartflow support?

Smartflow is multi-provider. It routes across providers such as Anthropic, OpenAI, Google, AWS Bedrock, and Azure OpenAI, as well as internal and self-hosted models, through one control plane. See Smartflow.

Can I use my own self-hosted or open-weight models?

Yes. Smartflow routes to internal and self-hosted models the same way it routes to cloud providers, with the same policy and evidence. On-premises models stay inside your boundary.

Does APERION lock me into one model provider?

No. A runtime control plane exists to keep provider optionality. Smartflow holds a single policy and evidence layer while you change providers, which preserves your negotiating position when pricing or terms change. Compare APERION and LiteLLM or APERION and Portkey.

What happens when a provider has an outage or rate limit?

Smartflow supports multi-provider failover and routing, so traffic can shift to a permitted alternative rather than stopping. Routing rules are policy-driven.

We already standardized on one provider. Do we still need this?

Yes. Even with one provider, Smartflow gives you inline policy enforcement, visibility, and identity-bound evidence, and it preserves the option to move later. The runtime question does not go away because you chose a model.

Can policy route by data type or risk?

Yes. Maestro, the policy engine, can block, allow, route, redact, or require step-up based on user, data type, workload, model, and risk. See Maestro.

06

Compliance, audit & evidence

Evidence a regulator will accept, not a dashboard.

Which regulations and frameworks does APERION help with?

Smartflow produces evidence mapped to frameworks including the EU AI Act, FINRA, DORA, NIST AI RMF, HIPAA, and SEC requirements. The Regulatory Examination Suite assembles examiner-ready packages. See examination readiness.

What is the Regulatory Examination Suite?

It is APERION's audit and evidence layer. It turns identity-bound runtime records into queryable, examiner-ready packages, so producing AI control evidence is a single call rather than a reconstruction project.

Are policy documents enough for a regulator?

Regulators increasingly ask for evidence of control, not statements of intent. A policy document describes what should happen. APERION records what did happen, bound to a verified identity, which is what holds up in an exam.

How does APERION help with the EU AI Act?

Smartflow enforces human-oversight and data controls at runtime and records the evidence the EU AI Act expects for higher-risk systems. See EU AI Act readiness.

How are audit logs protected?

Records are tamper-evident and bound to a verified identity, so the log is a third-party-grade account of what happened, not a narrative the agent wrote about itself.

How does APERION handle PII and PHI?

Smartflow detects sensitive data in prompts and can block or redact it before it reaches a model that is not permitted to receive it. This is enforced inline. See Industries.

Can we review APERION's own security documentation?

Yes. Security documentation and attestations are available to prospects under review. Request them through the contact page.

How long is evidence retained?

Retention is configurable to your regulatory and internal requirements, and because Smartflow runs in your environment, the records stay under your control. See the docs.

07

Fitting your existing stack

APERION composes with what you already run.

Isn't Microsoft Purview the runtime layer?

Purview governs data inside the Microsoft stack. The runtime plane is the call path between any agent and any model, including on-premises and non-Microsoft. Adjacent layer, not the same one.

We have ServiceNow AI Control Tower. Why APERION?

AI Control Tower governs the workflow agent: which agent runs and what it connects to. APERION governs what that agent sends to the model and what comes back. Different planes. APERION composes with it rather than competing.

We're deploying Microsoft Agent 365. Where does APERION fit?

Agent 365 orchestrates agents. APERION sits underneath, in the data path, inspecting and recording what those agents send to models. It runs on-premises and across providers, which the workflow plane does not.

How does APERION relate to detect-and-respond AI security tools?

Detect-and-respond tools watch for threats and alert after the fact. APERION enforces inline, so a blocked prompt never reaches the model, and it binds every action to identity for evidence. Enforcement and evidence, not only detection.

Do I keep my identity provider?

Yes. APERION composes with Okta, Microsoft Entra, Active Directory, Veza, SGNL, and SAML or Kerberos single sign-on. Smartflow reads identity over OIDC and carries it into the runtime record. It does not replace your identity provider.

Do I keep my API gateway?

Yes. Your API gateway handles REST traffic. APERION handles the AI boundary: prompts, responses, and tool calls. They operate at different layers. See APERION and Cloudflare AI Gateway.

How does APERION compare to other AI gateways and governance tools?

The difference is inline enforcement, on-premises deployment, agent identity, and identity-bound regulatory evidence in one runtime layer, rather than cloud-only observability. See the comparison pages, for example APERION and TrueFoundry or APERION and Credo AI.

08

Industries

The same runtime control, mapped to each regulated context.

What does APERION do for financial services?

It gives banks and insurers inline control over what agents send to models, provider optionality, and identity-bound evidence for FINRA, DORA and model inventory. The data plane stays inside the institution. See Industries.

What about insurance?

The same runtime control and evidence requirements as banking, applied to claims, underwriting, and customer-facing AI, with sensitive data kept inside the boundary.

How does APERION support healthcare?

Smartflow detects PHI and blocks it from reaching a model that is not permitted to receive it, enforces information barriers at the model boundary, and produces provenance records aligned with 21 CFR Part 11 and validated-system expectations. See Industries.

How does APERION support defense and national security?

In May 2026 the Five Eyes cyber agencies published joint guidance on agentic AI in critical infrastructure. The controls they describe map to a runtime architecture: cryptographic agent identity, a trusted registry, controls at every data boundary, human control points, and identity-bound accountability. APERION runs these on-premises and air-gapped. See Industries.

Can APERION govern shadow AI?

Yes. Smartflow gives a single inline point to discover and govern fragmented AI use across business units. See governing shadow AI.

Can APERION help reduce AI spend?

Yes. The gateway turns unbounded model usage into governed spend with attribution, budget controls, semantic caching, and provider optionality. See AI cost optimization.

09

APERION Shield (open source)

The open front door to the runtime plane.

What is APERION Shield?

Shield is APERION's open-source middleware for governing Model Context Protocol traffic. It inspects MCP tool calls and applies policy, and it is the open front door to Smartflow's runtime governance. It is on GitHub.

What license is Shield under?

Apache 2.0. You can run it, read the source, and build on it.

How does Shield decide what to flag?

Shield ships with a rule set and a five-signal scoring model that aims to flag genuine risks while letting normal operations through. In testing against real command traffic it passed legitimate operations through at a high rate. See the repository for detail.

How does Shield relate to Smartflow?

Shield governs MCP at the open-source layer. Smartflow is the full runtime control plane: multi-provider gateway, policy engine, agent identity, and the audit and evidence layer, built for regulated on-premises deployment. Shield is the entry point; Smartflow is the enterprise product.

Can I use Shield without Smartflow?

Yes. Shield is standalone and open source. Smartflow is for teams that need the full runtime plane and regulatory evidence.

Where are the developer docs?

Developer documentation is at the documentation, and the source is on GitHub.

10

Pilots, pricing & getting started

How a first deployment begins.

How do we get started?

Most engagements begin with a scoped proof of concept in one team or business unit, then expand. Use the contact page to scope one.

Do you offer a pilot or proof of concept?

Yes. A scoped proof of concept runs in your environment so you can see inline enforcement and evidence on your own traffic before expanding.

How is APERION priced?

Smartflow is enterprise software priced per deployment. Pricing depends on scope and environment, so it is set with sales rather than published. Ask for a quote through the contact page.

Who is the buyer?

Usually the CISO and the Chief Risk Officer, with the CIO involved where workflow-agent platforms are in play. Each layer of the Trust Fabric maps to a distinct owner.

How long does deployment take?

Because Smartflow inserts inline without application rewrites, a scoped deployment is measured in weeks, not quarters. Specifics depend on environment and integrations.

Where can developers and researchers learn more?

Start with the resources and the documentation, plus the open-source Shield repository. For runtime-governance analysis and incident coverage, see the WOPR Report and the blog.